diff options
| author | Mickaël Salaün <mic@digikod.net> | 2026-09-18 20:50:29 +0200 |
|---|---|---|
| committer | Mickaël Salaün <mic@digikod.net> | 2026-09-20 11:08:05 +0200 |
| commit | 0889db596a25ecde210e66fa0db70bc6a6d91f6c (patch) | |
| tree | ec1ebff23f21605d0fad839c7a14d2aaf5b852ac /tools | |
| parent | 7ad69ac63315506e2091bf46d5c96c49f6ce439e (diff) | |
| download | linux-0889db596a25ecde210e66fa0db70bc6a6d91f6c.tar.gz linux-0889db596a25ecde210e66fa0db70bc6a6d91f6c.zip | |
landlock: Report the effective signal number
The signal-scope denial callback identifies its target but not the
effective signal. This loses permission-probe signal zero and makes the
file-owner hook's zero sentinel ambiguous.
Append an int signal argument to the typed-BPF callback. Preserve sig,
including zero, in hook_task_kill(). In hook_file_send_sigiotask(),
translate signum zero to SIGIO at the producer, where its meaning is
known.
Carry the effective signal and target domain ID in a private,
stack-backed context consumed synchronously. This requires no allocation
or task reference in the interrupt-capable file-owner path. Gate this
context and the remaining scope-only domain IDs with CONFIG_TRACEPOINTS.
Keep the tracefs record and audit output unchanged.
Cc: Günther Noack <gnoack@google.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Fixes: bb91730f16c0 ("landlock: Add tracepoints for ptrace and scope denials")
Link: https://patch.msgid.link/20260918185036.608651-7-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Diffstat (limited to 'tools')
0 files changed, 0 insertions, 0 deletions
